fix: wrong title and author for CVE-2019-14287.yaml
parent
b2e48fb11f
commit
4989a2d085
|
@ -1,8 +1,8 @@
|
|||
id: CVE-2019-14287
|
||||
|
||||
info:
|
||||
name: GameOver(lay) - Local Privilege Escalation in Ubuntu Kernel
|
||||
author: princechaddha
|
||||
name: Sudo <= 1.8.27 - Security Bypass
|
||||
author: daffainfo
|
||||
severity: high
|
||||
description: |
|
||||
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
|
||||
|
|
Loading…
Reference in New Issue